7.8
CVSSv2

CVE-2009-2922

Published: 21/08/2009 Updated: 14/02/2024
CVSS v2 Base Score: 7.8 | Impact Score: 6.9 | Exploitability Score: 10
VMScore: 785
Vector: AV:N/AC:L/Au:N/C:C/I:N/A:N

Vulnerability Summary

Absolute path traversal vulnerability in pixaria.image.php in Pixaria Gallery 2.0.0 up to and including 2.3.5 allows remote malicious users to read arbitrary files via a base64-encoded file parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

pixaria pixaria gallery 2.3.5

pixaria pixaria gallery 2.0.0

Exploits

<?php ini_set("max_execution_time",0); print_r(' || || | || o_,_7 _|| _o_7 _|| q_|_|| o_///_, ( : / (_) / ( ___________________ ...